Vite Frontend Framework Vulnerability in JavaScript Tooling
CVE-2025-58751
What is CVE-2025-58751?
A vulnerability in Vite, a popular frontend tooling framework, enables unauthorized file serving when specific conditions are met. If applications expose the Vite dev server to the network and utilize symlinks in the public directory, attackers can serve files that match public directory names, effectively bypassing critical server-side restrictions. This issue has been resolved in versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, underscoring the importance of updating to the latest software releases to maintain security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
vite < 5.4.20 < 5.4.20
vite >= 6.0.0, < 6.3.6 < 6.0.0, 6.3.6
vite >= 7.0.0, < 7.0.7 < 7.0.0, 7.0.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
